• News/
  • https://www.theregister.com/2025/12/26/end_of_year_tabletop_exercises/

From AI to analog, cybersecurity tabletop exercises look a little different this year

The Register
·
Jessica Lyons
·
Published Dec 26, 2025
·
Updated

It's the most wonderful time of the year … for corporate security bosses to run tabletop exercises, simulating a hypothetical cyberattack or other emergency, running through incident processes, and practicing responses to ensure preparedness if when a digital disaster occurs. "We're ultimately testing how resilient is the organization," said Palo Alto Networks Chief Security Intelligence Officer Wendi Whitmore in an interview with The Register. "It's not if we get attacked, it's: How quickly do we respond and contain these attacks." And this year, organizations need to account for the speed of AI, both in terms of how attackers use these tools to find and exploit bugs, and how defenders can use AI in their response. "Threat actors are exploiting CVEs at an increased rate with AI," Google Cloud's Office of the CISO Public Sector Advisor Enrique Alvarez told The Register. "Tabletop exercises should consider a scenario where a CVE is published affecting a software system in use by the company with an immediate exploit via a cyber adversary." Whitmore said her threat analysts see a vulnerability released with exploits attempted within five minutes. "On the defender side, like our own SOC: We're looking at 90 billion attack events coming in per day, which we can synthesize down into 26,000 that are correlated, and then one per day that requires human manual intervention of tier-three analysts to dive in, and run additional queries and analysis," she added. Indeed, if 2025 taught u...

Read full article

Affected Software

4 affected components
Google Cloud Office of the CISO
Palo Alto Networks Security Intelligence
Mandiant Consulting
Microsoft Threat Protection
Free Weekly Intel

Don't miss critical vulnerabilities

Join thousands of security professionals who receive our weekly digest of trending CVEs, zero-days, and exploited vulnerabilities.

No spam. Unsubscribe anytime.

Frequently Asked Questions

1

What is the main topic of this article?

The article discusses the evolving nature of cybersecurity tabletop exercises in response to simulated cyberattacks and emergencies.

2

What security implications are discussed in the article?

The article highlights the importance of preparing for cyber incidents through realistic simulations to improve response strategies.

3

Which organizations are mentioned as utilizing tabletop exercises?

The article references various corporate security leaders and product vendors who conduct these exercises, including Google Cloud and Microsoft.

4

What products or software are affected by the discussed tabletop exercises?

The exercises involve tools and services from vendors such as Google Cloud Office of the CISO, Palo Alto Networks Security Intelligence, Mandiant Consulting, and Microsoft Threat Protection.

5

What skills do tabletop exercises aim to improve within organizations?

Tabletop exercises aim to enhance incident response skills, crisis management, and inter-departmental collaboration during a cyber incident.

Contact

SecAlerts Pty Ltd.
132 Wickham Terrace
Fortitude Valley,
QLD 4006, Australia
info@secalerts.co
By using SecAlerts services, you agree to our services end-user license agreement. This website is safeguarded by reCAPTCHA and governed by the Google Privacy Policy and Terms of Service. All names, logos, and brands of products are owned by their respective owners, and any usage of these names, logos, and brands for identification purposes only does not imply endorsement. If you possess any content that requires removal, please get in touch with us.
© 2026 SecAlerts Pty Ltd.
ABN: 70 645 966 203, ACN: 645 966 203